Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →The Canadian Program for Cyber Security Certification is now mandatory on select federal defence contracts, and Level 2 brings an external assessor in April 2027. We run both: the done-for-you Level 1 self-assessment against 13 requirements, and full Level 2 readiness against all 98 requirements of ITSP.10.171, including the System Security Plan, evidence, and a mock assessment. If you also supply the US Department of Defense, the same program covers CMMC Level 2. Led by a published security researcher, run from Toronto.
The CPCSC is Public Services and Procurement Canada's new mandatory cyber security certification for the defence supply chain, Canada's counterpart to the U.S. CMMC. Level 1 became available to suppliers on April 1, 2026, and starts appearing in select contracts this summer. Level 2, which is verified by an external assessor rather than self-attested, follows in April 2027. If your certification is not in place when a solicitation closes, you are out of the running. Requirements also flow down to subcontractors who touch the protected information. If you are still figuring out where you stand, our CPCSC guide walks through the requirements before you scope a paid engagement.
CPCSC controls come from ITSP.10.171, the Canadian Centre for Cyber Security's profile of NIST SP 800-171. The Level 1 subset is mapped against CAN/DGSI 104 so the work you do also counts toward broader Canadian baseline controls. Level 2 opens up the full 98 requirements across all 17 families.
The sensitivity of the information in a given solicitation decides whether you need Level 1, 2, or 3. You do not choose your level; the contract does. We cover Level 1 and Level 2, and help you confirm early which one your pipeline will trigger so you are ready before the bid lands rather than after.
Level 1 is a judgement call you attest to. Level 2 is an external assessment: an accredited certification body samples your evidence against every applicable objective and interviews the people who run the controls. That means a real assessment boundary, a System Security Plan, a POA&M, and controls that have been operating long enough to leave a trail. Budget 9 to 12 months, not weeks.
Level 1 is a self-assessment you re-attest every year through the Canada Buys procurement platform. Level 2 adds an annual affirmation between assessment cycles. We build the evidence and cadence so renewal is routine, not a fire drill.
We deliver readiness at both tiers most suppliers will actually face: Level 1, the self-assessed entry tier, and Level 2, the externally assessed tier that lands in April 2027. Here is what each one covers.
Annual self-assessment, self-attested through Canada Buys. 71 assessment objectives drawn from 6 of the 17 ITSP.10.171 control families:
Assessed by a certification body accredited by the Standards Council of Canada, then affirmed annually. All 17 ITSP.10.171 families, adding the 11 that Level 1 leaves out:
For suppliers who sell to the US Department of Defense as well. Assessed by a C3PAO on a three-year cycle, scored and affirmed in SPRS:
CPCSC also defines a Level 3 for the most sensitive contracts, assessed directly by National Defence against roughly 200 requirements. That tier is rare among SMB suppliers. If a solicitation puts you there, we will say so during scoping and bring in the right partner rather than stretch to cover it.
Requirement counts reflect the programs as published by PSPC, the Standards Council of Canada, and the US DoD for 2026 and are confirmed against your specific solicitation during scoping.
The programme is phasing in rather than landing at once, and which phase catches you depends on what you bid on rather than on your size. The dates below are the published rollout; the requirement that matters is whichever one your next solicitation names.
| Phase | What changes | What to do about it |
|---|---|---|
| Phase 1 From April 2026 |
Level 1 requirements become available, covering the 13 baseline security requirements on a self-assessed basis. | Run the Level 1 self-assessment now. It is the cheapest phase to be ready for and the one most suppliers will meet first. |
| Phase 2 From summer 2026 |
Level 1 starts appearing as a condition inside live solicitations rather than as guidance. | Have the attestation in place before a bid needs it. Readiness after the solicitation drops is readiness that arrives late. |
| Phase 3 April 2027 to March 2028 |
Levels 2 and 3 phase in. Level 2 covers 98 requirements drawn from ITSP.10.171 and brings an external assessor rather than a self-assessment. | If you handle protected information, start Level 2 gap work well ahead of the window. The gap between 13 and 98 requirements is not closed in a quarter. |
The certification decision is not ours to make. CPCSC certification rests with the Government of Canada programme, and Level 2 assessments are performed by an external assessor. We run the readiness work, the self-assessment and the evidence, and we say plainly which parts we cannot sign. The same list is on our internal audit page.
A Level 1 engagement runs 2 to 5 weeks depending on how much foundation already exists. Level 2 is a program, not a project: 6 to 12 months from scoping to an assessment-ready state, driven mostly by how much remediation the gap assessment turns up and how long controls need to run before an assessor can sample them. Below is what you walk away with.
CPCSC is new, but the underlying work (access control, authentication, evidence discipline) is the AppSec and compliance work we have done for years.
We are based in Toronto and work to the Canadian standards CPCSC is built on (ITSP.10.171 and CAN/DGSI 104), not a U.S. CMMC playbook bolted onto a Canadian form. We know which control maps to which assessment objective on the Canada Buys attestation. When a supplier sells to both governments, we map the evidence once and use it for CPCSC Level 2 and CMMC Level 2 rather than running two programs.
Our founder is a published security researcher with multiple CVEs, and we have taken startups from zero to a passed SOC 2 Type II audit. The discipline that survives an external auditor is the same discipline that survives a CPCSC certification body, which is exactly what Level 2 asks of you.
We are a readiness and advisory partner, not a certification body, and the rules keep those roles separate for good reason. We close gaps, author the SSP and POA&M, build evidence, and run a mock assessment against the objectives your assessor will use. For Level 1 we complete the self-assessment with you. For Level 2 we prepare you for an accredited certification body, help you select and schedule one, and sit with you through the assessment. The certificate comes from them, not from us.
Four phases. Level 1 engagements stop after phase three. Fixed scope, no surprises on the invoice.
We confirm which level your contracts require, define the boundary of the systems that handle protected information, and assess your current state against every applicable ITSP.10.171 requirement and assessment objective. At Level 2 that means all 98 requirements, and the boundary decision is the single biggest lever on your cost. You get a clear gap list ranked by effort and risk.
We help your team close the gaps and produce the evidence each requirement needs: policies, configurations, access reviews, logging, training records, and the supporting documentation behind them. At Level 2 this phase also produces your System Security Plan and the Plan of Action and Milestones for anything still open.
For Level 1 we complete and file the self-assessment with you on Canada Buys. For Level 2 we run a mock assessment against the same objectives an accredited certification body will use: we sample your evidence, interview your control owners the way an assessor will, and hand you a findings list while there is still time to fix it.
For Level 2 we help you select and schedule an accredited certification body, prepare your team for interviews, and stay in the room through the assessment via our auditor management and advocacy service. Then we set the maintenance cadence: annual affirmation, evidence refresh, and re-assessment planning, so you stay eligible without scrambling.
Tell us which contracts you are chasing, on either side of the border. We will tell you the level you need and scope the readiness work in one call.
Book a CallThe Canadian Program for Cyber Security Certification (CPCSC) is a mandatory cyber security certification program for contractors and subcontractors bidding on select Government of Canada defence contracts. It is led by Public Services and Procurement Canada (PSPC), with certification bodies accredited by the Standards Council of Canada and the highest-level assessments conducted by National Defence. It is Canada's counterpart to the U.S. CMMC and is built on the ITSP.10.171 control set, Canada's profile of NIST SP 800-171.
Level 1 requires an annual self-assessment against 13 security requirements and is self-attested. Level 2 requires an external assessment led by a certification body accredited by the Standards Council of Canada, plus an annual affirmation, against the 98 requirements of ITSP.10.171. Level 3 requires assessments conducted by National Defence plus an annual affirmation, against roughly 200 requirements. The level required is set by the sensitivity of the information in a given contract.
Level 1 asks suppliers to confirm the implementation status of 13 security requirements drawn from 6 of the 17 ITSP.10.171 control families, totalling 71 assessment objectives. The families cover access control, identification and authentication, media protection, physical protection, system and communications protection, and system and information integrity. The self-assessment is completed annually and attested through the Canada Buys procurement platform.
Level 2 covers all 98 security requirements in ITSP.10.171, across all 17 control families, and is verified by an external assessment led by a certification body accredited by the Standards Council of Canada rather than by self-attestation. You need a defined assessment boundary, a System Security Plan that describes how every applicable requirement is met, a Plan of Action and Milestones for anything outstanding, working evidence an assessor can sample, and staff who can explain how each control operates day to day. Certification is followed by an annual affirmation. Level 2 requirements are expected in contracts from April 2027.
Yes. CMMC Level 2 covers the 110 security requirements of NIST SP 800-171, assessed against 320 objectives by a C3PAO on a three-year cycle, with a score and annual affirmation posted in SPRS. Because ITSP.10.171 is Canada's profile of the same NIST standard, we run one readiness program for suppliers who sell to both the Department of National Defence and the US Department of Defense, and produce a single System Security Plan and evidence set mapped to both programs.
Level 1 became available to suppliers on April 1, 2026, and Level 1 requirements begin appearing in select defence contracts in summer 2026. Level 2, which requires an external assessment, follows in April 2027. Because assessor capacity is limited, Level 2 readiness work realistically starts 9 to 12 months before you need the certificate in hand.
Often yes. Certification requirements flow down the supply chain. If you handle the protected information covered by a contract, you can be required to hold the same level as the prime, even if you never contract directly with the government. We help map which of your contracts and data flows will trigger a requirement and at what level.
No, and you should be cautious of anyone who claims they can. Level 2 certificates are issued only by certification bodies accredited by the Standards Council of Canada, Level 3 is assessed by National Defence, and CMMC Level 2 certificates come from an authorized C3PAO. Readiness and certification have to stay separate. We are the readiness partner: we close your control gaps, author the SSP and POA&M, build the evidence, run a mock assessment against the same objectives your assessor will use, and stay with you through the assessment itself so there are no surprises.
Track record
We are deliberately not a large firm, and we would rather show you the work than a wall of logos. Here is what is behind the advice.
Six published CVEs, of which two show the range. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, and it handed defenders a way to shut down attacker infrastructure. CVE-2026-42626, issued through MITRE, is a denial-of-service flaw in HP ENVY 5000 series printers: the raw printing port enforces no connection timeout and no session limit, so one unauthenticated device on the same network can hold the printer offline until somebody physically restarts it.
That second one is the reason this belongs on a compliance page. An asset nobody thinks of as a computer, sitting on a flat network, taken down by a device that never had to authenticate. Auditors ask how controls fail. Finding out first-hand is what separates a policy that reads well from one that holds up when somebody asks for the evidence behind it.
Before founding traztech, Jacob was Head of Operations at Humera, a venture-backed US security company whose bot-detection platform sits in the request path of its customers' applications, and he built its compliance programme in-house: no report, no policies, no documented controls at the start. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15, having inventoried 60-plus assets and put a five-stage change-approval flow in front of production.
The platform stayed at 99.9% uptime and sub-100ms latency throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to add to a system people are already depending on. That programme is why we sell fixed windows rather than open-ended retainers.
For a Waterloo data centre operator we scoped and assessed SOC 2 Type II (Security, Availability and Confidentiality) against ISO 27001:2022 including the Climate Action Amendment, run together rather than one after the other. Scope covered the production campus, a datacenter platform, an AI compute platform and a self-hosted collaboration stack, written so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.
For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.
Before you go
Short, practical notes on CPCSC Readiness. Unsubscribe in one click, and replies reach me directly.
From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.